Sample viewer

vx.netlux.org/Trojan.DOS.Ribbon

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:50:35.341958418Z 53 PC: 131ea | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:50:35.34340989Z 53 PC: 131ea | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:50:35.344417153Z 53 PC: 131ea | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:50:35.345386522Z 53 PC: 131ea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:50:35.346786619Z 53 PC: 131ea | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:50:35.347784312Z 53 PC: 131ea | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:50:35.348752986Z 53 PC: 131ea | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:50:35.350360328Z 53 PC: 131ea | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:50:35.3515502Z 53 PC: 131ea | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:50:35.352689276Z 53 PC: 131ea | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:50:35.354889643Z 53 PC: 131ea | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:50:35.355947843Z 53 PC: 131ea | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:50:35.3569143Z 53 PC: 131ea | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:50:35.35792782Z 53 PC: 131ea | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:50:35.359289253Z 53 PC: 131ea | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:50:35.360234227Z 53 PC: 131ea | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:50:35.361192607Z 53 PC: 131ea | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:50:35.362654503Z 53 PC: 131ea | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:50:35.363496335Z 53 PC: 131ea | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:50:35.364290561Z 37 PC: 131ff | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:50:35.365516833Z 37 PC: 13207 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:50:35.366223789Z 37 PC: 1320f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:50:35.366944991Z 37 PC: 13217 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:50:35.368403899Z 68 PC: 13672 | I/O control for devices (Set for = '�&���>v')
2018-12-17T21:50:35.537945361Z 64 PC: 13608 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T21:50:35.539124748Z 37 PC: 13341 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:50:35.540491208Z 37 PC: 13341 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:50:35.541539685Z 37 PC: 13341 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:50:35.542475112Z 37 PC: 13341 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:50:35.544095299Z 37 PC: 13341 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:50:35.545166021Z 37 PC: 13341 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:50:35.546157251Z 37 PC: 13341 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:50:35.547721884Z 37 PC: 13341 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:50:35.548747582Z 37 PC: 13341 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:50:35.549759271Z 37 PC: 13341 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:50:35.551285473Z 37 PC: 13341 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:50:35.552302918Z 37 PC: 13341 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:50:35.553211336Z 37 PC: 13341 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:50:35.554579621Z 37 PC: 13341 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:50:35.555498719Z 37 PC: 13341 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:50:35.556368362Z 37 PC: 13341 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:50:35.557694868Z 37 PC: 13341 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:50:35.558620787Z 37 PC: 13341 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:50:35.559480249Z 37 PC: 13341 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:50:35.560658703Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.562555087Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.564350856Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.566823686Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.568725872Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.57061842Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.572974146Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.575016412Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.576969785Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.579424021Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.581394055Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.583293652Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.585675236Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.587751966Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.58991124Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.592636627Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.595131055Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.597071551Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.599686633Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.602103069Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.604392084Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.606748233Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.608680554Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.610131029Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.611891139Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.613314295Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.614688002Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.616531257Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.618038681Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.619941507Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.62309581Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.625527795Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.627354834Z 6 PC: 133c8 | Direct console I/O
2018-12-17T21:50:35.631214268Z 76 PC: 13380 | Terminate with return code (Return code = '200')